CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10084 | CVE-2004-1656 | Candidate | CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10085 | CVE-2004-1657 | Candidate | Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10086 | CVE-2004-1658 | Candidate | Kerio Personal Firewall 4.0 (KPF4) allows local users with administrative privileges to bypass the Application Security feature and execute arbitrary processes by directly writing to devicephysicalmemory to restore the running kernel"s SDT ServiceTable. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10087 | CVE-2004-1659 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10088 | CVE-2004-1660 | Candidate | PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php. | Assigned (20050221) | None (candidate not yet proposed) | View |
Page 19722 of 20943, showing 5 records out of 104715 total, starting on record 98606, ending on 98610